Live data from Hacker News

Coinbase Breach Notification

oag.ca.gov

131–140 of 287 posts

Re: Coinbase Breach Notification

#131

Earlier quoted context omitted.

I am a cryptocurrency enthusiast/advocate, but I've come to the realization that "being your own bank" is actually a terrifying and merciless burden. One small mistake has the potential to wipe you out and there is no way to get your funds back. Despite all the criticisms that come with "the banking system", banks do provide a lot of value to individuals. It is completely understandable that people would want to wrap…

> "being your own bank" is actually a terrifying and merciless burden It's amazing how many smart people take so long to realize why banks exist.

It’s also amazing how many smart people are completely ignorant of the common and routine failure modes of banks, and why hundreds of millions of people might want an alternative to that.

I just had to physically cross an ocean twice because my bank won’t send wires for more than $25k via their website, and that’s one of the gentler failure modes.

Here are some examples: https://old.reddit.com/r/fatFIRE/comments/pycgjx/what_in_the...

Retail banking in the USA is terrible.

Re: Coinbase Breach Notification

#132
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

And lack of KYC, which enables it to be used for ransomware payments

Re: Coinbase Breach Notification

#133
post #120

Earlier quoted context omitted.

There are multiple ways to avoid this, such as using an app that saves those keys (eg Authy) or using recovery keys.

But then bad guy just logs in to Authy with the same stolen credentials because most normal people will probably use the same credentials for everything, including Authy. And arguably, the smartest tech-savvy folk wouldn't be storing their 2FA keys in the cloud like Authy anyway. If your cloud account is protected by 2FA that's also in the cloud... it's turtles all the way down.

How do you “Log in” to Authy? It’s tied to your Apple/Google ID afaik and the 2fa codes are also protected with a passphrase.

Re: Coinbase Breach Notification

#134
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

I can write code that trades bitcoins without having to ask anyone for permission. Without getting into what Bitcoin will change about banking, I'd say that's pretty different from regular banking.

Re: Coinbase Breach Notification

#135
post #123

Earlier quoted context omitted.

> ... the attackers had to perform a "SIM swap" type attack on the users Minor nitpick: I find your framing problematic as it transfers "burden of security" to the end-users over a process that did not involve them: this was not an attack on the users - it was an attack on the telecoms infrastructure. I have a similar gripe against "identity theft", which really ought to be "fraud against corporation X, using false i…

I agree. From Coinbase's perspective, they ought to defend their infrastructure against fraud, whether that is a direct attack on the users, an attack on the users' telcos, or insider activity directly. From the telco's perspective, they have a responsibility to stop SMS and SIM fraud, and our regulations have failed to properly hold them accountable in this domain. I would add that the users have some responsibility…

I fully agree that users are not absolved of all responsibilities or vigilance (e.g. over passwords/devices). I think the legal framework has to be overhauled to clarify the culpability of all parties involved, rather than the current "Sucks to be you" attitude towards consumers, who are the least powerful, and have the least agency in these issues.

Re: Coinbase Breach Notification

#136

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

> you have to admit that you are far more likely to be compensated in the event of an attack if you are using a large exchange

This is only a recent phenomenon, and I don’t think it holds for all “large exchange[s]”.

Re: Coinbase Breach Notification

#137

One thing that cryptocurrencies achieved is they introduced a private key authentication at scale. For a moment, there was a hope that we can move to private key authentication mechanism. But, unfortunately, it was quickly rolled back by introduction of custodial wallets and we got pulled back into world of passwords.

sneak’s law: users can not (and a tiny subset of users that actually know how to, will not) securely manage* key material.

*manage: generate, transmit/sync, authenticate, back up

Discussion: https://youtu.be/9k4GP3Evh9c

I actually operate a business that exists solely as a result of this fact.

If you give a user a key, they will lose it. If they’re a customer, you need to have a back up plan for what happens when they lose their keys.

Re: Coinbase Breach Notification

#138
post #43

SMS-based 2FA needs to die.

It's the easiest to use because of the prevalence of phone numbers and transferability between phones. These properties that give it the best user experience also make it the worst form of 2FA. TOTP and hardware keys are more secure but they are easier to lock yourself out of the account.

Re: Coinbase Breach Notification

#139
post #30

> "We will be depositing funds into your account equal to the value of the currency improperly removed from your account at the time of the incident. Some customers have already been reimbursed -- we will ensure all customers affected receive the full value of what you lost. You should see this reflected in your account no later than today." I sympathize with the "Not your keys, not your coins" crowd, but you have to…

Wonder how many people follow this reasoning to the next logical conclusion and realize that there is literally nothing to differentiate the coins at all from regular banking except for the lure of speculation.

That is the logical conclusion of the institutions, since they are basically crypto banks. However the underlying coins are very different from the underlying asset in a bank, even if their use cases haven't come to fruition and the most common use case is speculation. The use cases that currently exist and are important, though probably not to users in this forum, are borderless transference and the ability to truly own your assets without a governing body or third party institution able to touch them. A significant portion of the world either: lacks institutional banking or is under an authoritarian / corrupt government that could seize their assets just because. Which means the current use cases are incredibly valuable to those individuals. For most users here coins are probably a novelty used for speculation or asset diversification.

Re: Coinbase Breach Notification

#140
post #2

Coinbase made everyone whole, and the attackers stole the credentials (not because of Coinbase's fault) ahead of time, and the attackers had to perform a "SIM swap" type attack on the users. "Breach" may be the required term for the Californian government, but this wouldn't qualify to most people as a traditional breach (i.e., compromise of Coinbase's infrastructure). Edit: California, not Canada. My bad.

It was not a simswap/simjack attack, they exploited an oversight in coinbase's password-reset 2fa to send the challenge code for one user to another user's phone number.

I haven't been able to verify these sort of claims any more than I've been able to speculate it was blanket telco Letters-of-Authorization (LoAs) [0][1] or classic SIM swaps that resulted in the account takeovers. I'm not claiming you're wrong, but given the timing of the LoA fraud and the attacks, it seemed likely to me that this was not an actual web vulnerability.

What makes you believe a specific exploit like that existed against Coinbase's 2FA? And if it existed, then why wasn't that caught in a routine pentest?

[0]: https://krebsonsecurity.com/2021/03/can-we-stop-pretending-s...

[1]: https://lucky225.medium.com/its-time-to-stop-using-sms-for-a...

Post reply on HN